<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>va properties - GoBlog</title>
	<atom:link href="https://blog.goreinnamah.com/blog/tag/va-properties/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.goreinnamah.com</link>
	<description>LOG ALL LOGS</description>
	<lastBuildDate>Fri, 21 Jul 2017 13:11:42 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://blog.goreinnamah.com/wp-content/uploads/2017/01/cropped-1-150x150.jpg</url>
	<title>va properties - GoBlog</title>
	<link>https://blog.goreinnamah.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Menambahkan Validation Authority pada EJBCA 6.2.0</title>
		<link>https://blog.goreinnamah.com/blog/2017/02/01/menambahkan-validation-authority-pada-ejbca/</link>
					<comments>https://blog.goreinnamah.com/blog/2017/02/01/menambahkan-validation-authority-pada-ejbca/#comments</comments>
		
		<dc:creator><![CDATA[Darius Go Reinnamah]]></dc:creator>
		<pubDate>Wed, 01 Feb 2017 08:00:50 +0000</pubDate>
				<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[Certification Authority]]></category>
		<category><![CDATA[ejbca]]></category>
		<category><![CDATA[jboss]]></category>
		<category><![CDATA[ocsp]]></category>
		<category><![CDATA[ocsp properties]]></category>
		<category><![CDATA[ocsp responder]]></category>
		<category><![CDATA[subca]]></category>
		<category><![CDATA[VA]]></category>
		<category><![CDATA[va properties]]></category>
		<category><![CDATA[va publisher]]></category>
		<category><![CDATA[validation authority]]></category>
		<guid isPermaLink="false">http://blog.goreinnamah.com/?p=295</guid>

					<description><![CDATA[<p>Sebelum memulai tahap ini, pastikan bahwa Management CA sudah terinstal dan berjalan dengan baik (Baca cara instalasi EJBCA disini). Setelah[...]</p>
<p>The post <a href="https://blog.goreinnamah.com/blog/2017/02/01/menambahkan-validation-authority-pada-ejbca/">Menambahkan Validation Authority pada EJBCA 6.2.0</a> first appeared on <a href="https://blog.goreinnamah.com">GoBlog</a>.</p>]]></description>
										<content:encoded><![CDATA[<p style="text-align: justify;">Sebelum memulai tahap ini, pastikan bahwa Management CA sudah terinstal dan berjalan dengan baik (Baca cara instalasi EJBCA <a href="http://blog.goreinnamah.com/blog/2017/01/27/instalasi-ejbca-6-2-0-pada-jboss-7-1-1-dan-ubuntu-16-04/"><strong>disini</strong></a>). Setelah sudah yakin kalau Management CA berjalan dengan baik, barulah kita bisa menambahkan fungsi validasi kepada server kita. Untuk proses validasi ini, Primekey memasukkan setiap proses yang  melakukan validasi sertifikat (CMP, OCSP, Distribusi CRL) sebagai bagian dari &#8220;Validation Authority&#8221;.</p>
<p style="text-align: justify;">Merujuk pada Diagram Layout logical ASCII berikut:</p>
<figure id="attachment_301" aria-describedby="caption-attachment-301" style="width: 849px" class="wp-caption aligncenter"><img fetchpriority="high" decoding="async" class="size-full wp-image-301" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/1-layout-ASCII.png" alt="" width="849" height="178" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/1-layout-ASCII.png 849w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/1-layout-ASCII-300x63.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/1-layout-ASCII-768x161.png 768w" sizes="(max-width: 849px) 100vw, 849px" /><figcaption id="caption-attachment-301" class="wp-caption-text">pic via ejbcacentos</figcaption></figure>
<p style="text-align: justify;">Apa yang tidak diperlihatkan oleh diagram ini adalah <strong>VA (Validation Authority)</strong> memiliki datasource Jboss tersendiri yang berbeda dari datasource yang digunakan oleh <strong>CA (Certifictaion Authority)</strong>. Namun, dalam environment standalone, koneksi ini mengarah ke database yang sama (database ejbca) yang digunakan oleh <strong>CA</strong>.</p>
<ul style="text-align: justify;">
<li style="text-align: justify;">Mendfinisikan datasource <strong>VA</strong> adalah tujuan utama dari file <strong>va-publisher.properties</strong> (file berada di /<strong>opt/ejbca/conf/</strong> setelah di copy dari <strong>/opt/ejbca/conf/sample/</strong>).</li>
<li style="text-align: justify;">seperti datasource <strong>CA</strong>, konfigurasi datasource <strong>VA</strong> juga akan ditambahkan ke dalam file <strong>standalone.xml</strong> selama deployment. (setelah file<strong> . properties</strong> yang spesifik dengan VA dibuat).</li>
<li style="text-align: justify;">Perlu dicatat bagaimana PrimeKey menggunakan istilah &#8220;Publisher&#8221;. Publisher ini digunakan untuk menggambarkan gagasan tentang informasi dari komponen &#8220;publishing&#8221; EJBCA (dari sebuah datasource) ke sebuah server terpisah pada sebuah instalasi EJBCA yang terdistribusi.</li>
<li style="text-align: justify;">Misalkan server standalone kita hanya &#8220;publishing&#8221; ke service VA-nya sendiri , kita masih membutuhkan &#8220;publisher&#8221; untuk dimasukkan dalam <strong>va-publisher.properties</strong>.</li>
<li style="text-align: justify;">file <strong>va.properties</strong> menjelaskan operasi VA secara umum seperti fungsi pemeriksaan kesehatan (<strong>healthcheck</strong>).</li>
<li style="text-align: justify;">file <strong>ocsp.properties</strong> mendefinisikan fungsionalitas protokol <strong>OCSP</strong>.</li>
<li style="text-align: justify;">File <strong>va.properties</strong> berisi instruksi spesifik bagaimana mengizinkan download <strong>CRL/OCSP</strong> alias untuk beberapa (multiple) instance CA.</li>
</ul>
<p style="text-align: justify;">Langkah pertama untuk menjalankan VA adalah membuat file-file properties yang terkait validasi pada direktori <strong>/opt/ejbca/conf</strong>. caranya:</p>
<pre><strong>cd /opt/ejbca/conf
</strong><strong>cp sample/ocsp.properties.sample ocsp.properties
</strong><strong>cp sample/va.properties.sample va.properties
</strong><strong>cp sample/va-publisher.properties.sample va-publisher.properties</strong></pre>
<h2 style="text-align: justify;"><strong>Konfigurasi file-file Validation Authority</strong></h2>
<h3 style="text-align: justify;"><strong>ocsp.properties</strong></h3>
<pre><strong>### Start ocsp.properties ###</strong>
 
<strong> # ------------ OCSP responder configuration ---------------------</strong>
 
<span style="color: #ff0000;"><strong> ocsp.enabled=true</strong></span>
<strong> #ocsp.enabled=false</strong>
 
<strong> # ini path untuk URL OCSP</strong>
<span style="color: #ff0000;"><strong> ocsp.contextroot=/ejbca/publicweb/status</strong></span>
<strong> #ocsp.contextroot=/status</strong>
 
<strong> # ini adalah DN dari CA yang akan merespon untuk serifikat yang gak dikenal</strong>
<span style="color: #ff0000;"><strong> ocsp.defaultresponder=CN=NamaCALo,O=PerusahaanLo,C=ID</strong></span>
 
<span style="color: #ff0000;"><strong> ocsp.includecertchain=true</strong></span>
<span style="color: #ff0000;"><strong> ocsp.includesignercert=true</strong></span>
<span style="color: #ff0000;"><strong> ocsp.responderidtype=keyhash</strong></span>
<span style="color: #ff0000;"><strong> ocsp.signaturealgorithm=SHA1WithRSA;SHA1WithECDSA;SHA1WithDSA</strong></span>
<span style="color: #ff0000;"><strong> ocsp.signingCertsValidTime=300</strong></span>
<span style="color: #ff0000;"><strong> ocsp.warningBeforeExpirationTime=10000</strong></span>
 
<span style="color: #ff0000;"><strong> ocsp.nonexistingisgood=false</strong></span>
 
<strong> #ocsp.nonexistingisgood.uri.1=.*/thisEndingIsGood$</strong>
<strong> #ocsp.nonexistingisgood.uri.2=^http://good.myhost.nu:8080/.*</strong>
<strong> #ocsp.nonexistingisbad.uri.1=.*/thisEndingIsBad$</strong>
<strong> #ocsp.nonexistingisbad.uri.2=^http://bad.myhost.nu:8080/.*</strong>
<span style="color: #ff0000;"><strong> ocsp.nonexistingisrevoked=false</strong></span>
<strong> #ocsp.nonexistingisrevoked.uri.1=.*/thisEndingIsRevoked$</strong>
<strong> #ocsp.nonexistingisrevoked.uri.2=^http://revoked.myhost.nu:8080/.*</strong>
 
<span style="color: #ff0000;"><strong> ocsp.expiredcert.retentionperiod = 31536000</strong></span>
<strong> #ocsp.expiredcert.retentionperiod = -1</strong>
 
<span style="color: #ff0000;"><strong> ocsp.untilNextUpdate = 0</strong></span>
<strong> #ocsp.999.untilNextUpdate = 50</strong>
<span style="color: #ff0000;"><strong> ocsp.revoked.untilNextUpdate = 0</strong></span>
<strong> #ocsp.999.revoked.untilNextUpdate = 50</strong>
<span style="color: #ff0000;"><strong> ocsp.maxAge = 30</strong></span>
<strong> #ocsp.999.maxAge = 100</strong>
<span style="color: #ff0000;"><strong> ocsp.revoked.maxAge = 30</strong></span>
<strong> #ocsp.999.revoked.maxAge = 100</strong>
 
<strong> #ocsp.extensionoid=</strong>
<strong> #ocsp.extensionclass=</strong>
 
<strong> #ocsp.uniddatsource=</strong>
<strong> #ocsp.unidtrustdir=</strong>
<strong> #ocsp.unidcacert=</strong>
<strong> #ocsp.signaturerequired=false</strong>
 
<strong> #ocsp.rekeying.trigging.password=</strong>
<strong> #ocsp.rekeying.wsurl = https://milton:8443/ejbca/ejbcaws/ejbcaws</strong>
<strong> #ocsp.rekeying.update.time.in.seconds=</strong>
<strong> #ocsp.rekeying.safety.margin.in.seconds=</strong>
<strong> #ocsp.rekeying.trigging.hosts=</strong>
 
<strong> # Default: false</strong>
<span style="color: #ff0000;"><strong> ocsp.trx-log = true</strong></span>
<span style="color: #ff0000;"><strong> ocsp.log-date = yyyy-MM-dd:HH:mm:ss:z</strong></span>
<strong> #ocsp.log-timezone = GMT</strong>
<strong> #ocsp.trx-log-pattern = \\$\\{(.+?)\\}</strong>
<strong> # The next line will probably line-wrap in your browser:</strong>
<strong> #ocsp.trx-log-order = ${SESSION_ID};${LOG_ID};${STATUS};${REQ_NAME}"${CLIENT_IP}";"${SIGN_ISSUER_NAME_DN}";"${SIGN_SUBJECT_NAME}";${SIGN_SERIAL_NO};"${LOG_TIME}";${REPLY_TIME};${PROCESS_TIME};${NUM_CERT_ID};0;0;0;0;0;0;0;"${ISSUER_NAME_DN}";${ISSUER_NAME_HASH};${ISSUER_KEY};${DIGEST_ALGOR};${SERIAL_NOHEX};${CERT_STATUS}</strong>
 
<span style="color: #ff0000;"><strong> ocsp.audit-log = true</strong></span>
<strong> #ocsp.audit-log-pattern = \\$\\{(.+?)\\}</strong>
<strong> # The next line will probably line-wrap in your browser:</strong>
<strong> #ocsp.audit-log-order = SESSION_ID:${SESSION_ID};LOG ID:${LOG_ID};"${LOG_TIME}";REPLY TIME:${REPLY_TIME};\nTIME TO PROCESS:${PROCESS_TIME};\nOCSP REQUEST:\n"${OCSPREQUEST}";\nOCSP RESPONSE:\n"${OCSPRESPONSE}";\nSTATUS:${STATUS}</strong>
<strong> #ocsp.log-safer = true</strong>
 
 
<strong> ### End ocsp.properties ###</strong></pre>
<figure id="attachment_309" aria-describedby="caption-attachment-309" style="width: 1010px" class="wp-caption aligncenter"><img decoding="async" class="size-full wp-image-309" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/3-ocsp-properties.png" alt="" width="1010" height="483" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/3-ocsp-properties.png 1010w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/3-ocsp-properties-300x143.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/3-ocsp-properties-768x367.png 768w" sizes="(max-width: 1010px) 100vw, 1010px" /><figcaption id="caption-attachment-309" class="wp-caption-text">ocsp.properties 1</figcaption></figure>
<figure id="attachment_311" aria-describedby="caption-attachment-311" style="width: 1011px" class="wp-caption aligncenter"><img decoding="async" class="size-full wp-image-311" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/4-ocsp-properties.png" alt="" width="1011" height="667" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/4-ocsp-properties.png 1011w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/4-ocsp-properties-300x198.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/4-ocsp-properties-768x507.png 768w" sizes="(max-width: 1011px) 100vw, 1011px" /><figcaption id="caption-attachment-311" class="wp-caption-text">ocsp.properties 2</figcaption></figure>
<figure id="attachment_312" aria-describedby="caption-attachment-312" style="width: 1010px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-312" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/5-ocsp-properties.png" alt="" width="1010" height="652" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/5-ocsp-properties.png 1010w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/5-ocsp-properties-300x194.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/5-ocsp-properties-768x496.png 768w" sizes="auto, (max-width: 1010px) 100vw, 1010px" /><figcaption id="caption-attachment-312" class="wp-caption-text">ocsp.properties 3</figcaption></figure>
<figure id="attachment_314" aria-describedby="caption-attachment-314" style="width: 1010px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-314" src="http://blog.goreinnamah.com/wp-content/uploads/2017/02/6-ocsp-properties.png" alt="" width="1010" height="612" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/02/6-ocsp-properties.png 1010w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/6-ocsp-properties-300x182.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/6-ocsp-properties-768x465.png 768w" sizes="auto, (max-width: 1010px) 100vw, 1010px" /><figcaption id="caption-attachment-314" class="wp-caption-text">ocsp.properties 4</figcaption></figure>
<figure id="attachment_315" aria-describedby="caption-attachment-315" style="width: 1010px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-315" src="http://blog.goreinnamah.com/wp-content/uploads/2017/02/7-ocsp-properties.png" alt="" width="1010" height="543" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/02/7-ocsp-properties.png 1010w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/7-ocsp-properties-300x161.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/7-ocsp-properties-768x413.png 768w" sizes="auto, (max-width: 1010px) 100vw, 1010px" /><figcaption id="caption-attachment-315" class="wp-caption-text">ocsp.properties 5</figcaption></figure>
<figure id="attachment_316" aria-describedby="caption-attachment-316" style="width: 1010px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-316" src="http://blog.goreinnamah.com/wp-content/uploads/2017/02/8-ocsp-properties.png" alt="" width="1010" height="666" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/02/8-ocsp-properties.png 1010w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/8-ocsp-properties-300x198.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/8-ocsp-properties-768x506.png 768w" sizes="auto, (max-width: 1010px) 100vw, 1010px" /><figcaption id="caption-attachment-316" class="wp-caption-text">ocsp.properties 6</figcaption></figure>
<h3 style="text-align: justify;"><strong>va.properties</strong></h3>
<pre><strong>### Start va.properties ###</strong>
 
<strong> #------------------- Validation Authority (VA) Healthcheck settings -------------</strong>
<span style="color: #ff0000;"><strong> ocsphealthcheck.signtest=true</strong></span>
<span style="color: #ff0000;"><strong> ocsphealthcheck.checkSigningCertificateValidity=true</strong></span>
 
 
<strong> # PrimeKey's instructions here are particularly terrible. Let me see if I can translate:</strong>
 
<strong> # In this last setting, we will define an alias 'root' for a particular RFC 4985 Section 2.1 "Search Key ID Hash" or "sKIDHash"</strong>
<strong> # Our example sKIDHash is:'O4RdnGNf3WPioslAQsX71aR1/MI'</strong>
<strong> # sKIDHashes are unique to each CA instance that you run on your ejbca server.</strong>
 
<strong> # This has the effect of making the following URLs equivalent. This simplifies the entries in your certificates that specify</strong>
<strong> # CRL/OCSP download locations, and grants the ability to have simultaneous CRL/OCSP download URLs</strong>
<strong> # Typically, you will define a unique sKIDHash alias for each of your CA instances.</strong>
 
<strong> # Example URL for certificate search: http://myhost.com:8080/certificates/search.cgi?sKIDHash=O4RdnGNf3WPioslAQsX71aR1/MI</strong>
<strong> # This will be the same as http://myhost.com:8080/certificates/search.cgi?alias=root</strong>
 
<strong> # Example URL for CRL download: http://myhost.com:8080/crls/search.cgi?sKIDHash=O4RdnGNf3WPioslAQsX71aR1/MI</strong>
<strong> # is the same as http://myhost.com:8080/crls/search.cgi?alias=root</strong>
 
<strong> # Example URL for Delta CRL download: http://myhost.com:8080/crls/search.cgi?sKIDHash=O4RdnGNf3WPioslAQsX71aR1/MI&amp;delta=</strong>
<strong> # is the same as http://myhost.com:8080/crls/search.cgi?alias=root&amp;delta=</strong>
 
 
<strong> # To determine the hash to use here, navigate to http://yourhost.com:8080/crls/search.cgi or http://yourhost.com:8080/certificates/search.cgi</strong>
<strong> # (Omit the :8080 if you are browsing from somewhere other than localhost)</strong>
<strong> # This URL will give you a list of the unique validation identifiers (including the sKIDHash) for each of your defined CAs.</strong>
 
<strong> # Copy the sKIDHashes for the CA instances. Remember, you will have more than one, and you can omit the Management CA as it is solely internal to ejbca.</strong>
<strong> # Add an entry like the one below for each of your CAs, paste the sKIDHash into the entry, then redeploy ejbca.</strong>
 
 
<strong> #va.sKIDHash.alias.root=O4RdnGNf3WPioslAQsX71aR1/MI</strong>
 
<strong> ### End va.properties ###
</strong></pre>
<figure id="attachment_317" aria-describedby="caption-attachment-317" style="width: 1185px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-317" src="http://blog.goreinnamah.com/wp-content/uploads/2017/02/8-va-properties-1.png" alt="" width="1185" height="265" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/02/8-va-properties-1.png 1185w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/8-va-properties-1-300x67.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/8-va-properties-1-768x172.png 768w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/8-va-properties-1-1024x229.png 1024w" sizes="auto, (max-width: 1185px) 100vw, 1185px" /><figcaption id="caption-attachment-317" class="wp-caption-text">va.properties</figcaption></figure>
<h3 style="text-align: justify;"><strong>va-publisher.properties</strong></h3>
<pre><strong>Start va-publisher.properties ###
 
 #-------------- Validation Authority(VA) publisher db configuration-------------------------
 # All the "ocsp-database.*" properties are used to configure the VA connection to the database.
 #
 # In "PrimeKeyese": Configure these options if you are configuring EJBCA that will publish 
 # certificates to a VA.
 
 
<span style="color: #ff0000;"> ocsp-datasource.jndi-name=OcspDS</span>
<span style="color: #ff0000;"> ocsp-database.url=jdbc:mysql://127.0.0.1:3306/ejbcadb?characterEncoding=UTF-8</span>
<span style="color: #ff0000;"> ocsp-database.driver=com.mysql.jdbc.Driver</span>
<span style="color: #ff0000;"> ocsp-database.username=ejbcadbuser</span>
 
 
 # password Databasenya diatur di sini
 <span style="color: #ff0000;">ocsp-database.password=asalaja</span>
 
 ### End va-publisher.properties ###
</strong></pre>
<figure id="attachment_319" aria-describedby="caption-attachment-319" style="width: 918px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-319" src="http://blog.goreinnamah.com/wp-content/uploads/2017/02/9-va-publisher.png" alt="" width="918" height="477" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/02/9-va-publisher.png 918w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/9-va-publisher-300x156.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/9-va-publisher-768x399.png 768w" sizes="auto, (max-width: 918px) 100vw, 918px" /><figcaption id="caption-attachment-319" class="wp-caption-text">va-publisher.properties</figcaption></figure>
<p style="text-align: justify;">Untuk membuat VA berjalan, kita perlu mengeksekusi beberapa perintah yang sama sebelum kita melakukan deployment awal:</p>
<pre><strong>su - jboss
</strong><strong>cd /opt/jboss/bin
</strong><strong>ps -ax | grep jboss
</strong><strong>kill -9 &lt;proses_jboss&gt;
</strong><strong>chown -R jboss:jboss /opt/jboss-as-7.1.1.Final
</strong><strong>chown -R jboss:jboss /opt/ejbca_ce_6_2_0
</strong><strong>nohup ./standalone.sh -b 0.0.0.0 -bmanagement=0.0.0.0 &amp;</strong>
<strong>cd /opt/ejbca</strong>
<strong>ant deploy</strong></pre>
<figure id="attachment_322" aria-describedby="caption-attachment-322" style="width: 751px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-322" src="http://blog.goreinnamah.com/wp-content/uploads/2017/02/10-build-success.png" alt="" width="751" height="156" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/02/10-build-success.png 751w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/10-build-success-300x62.png 300w" sizes="auto, (max-width: 751px) 100vw, 751px" /><figcaption id="caption-attachment-322" class="wp-caption-text">hasil ant deploy jika berhasil (Validation Authority)</figcaption></figure>
<p style="text-align: justify;">ingat bahwa dalam <strong>ocsp.properties</strong>, kita mendefinisikan &#8220;<strong>ocsp.defaultresponder</strong>&#8220;. Ini adalah DN dari CA yang akan menjawab permintaan OCSP untuk CA yang tidak diketahui. Primekey merekomendasikan agar kita menggunakan <strong>Management CA (Root CA)</strong> untuk ini. Namun, alangkah lebih baiknya bila kuta menggunakan <strong>default CA (Sub CA)</strong> untuk tujuan ini atau kita menggunakan Sebuah <strong>SubCA</strong> yang kita buat terlebih dahulu.</p>
<p style="text-align: justify;">sampai SubCA itu berhasil dibuat, kita akan melihat pesan berikut dalam console log (nohup.out):</p>
<figure id="attachment_323" aria-describedby="caption-attachment-323" style="width: 1352px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-323" src="http://blog.goreinnamah.com/wp-content/uploads/2017/02/11-ocsp-responder-.png" alt="" width="1352" height="55" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/02/11-ocsp-responder-.png 1352w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/11-ocsp-responder--300x12.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/11-ocsp-responder--768x31.png 768w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/11-ocsp-responder--1024x42.png 1024w" sizes="auto, (max-width: 1352px) 100vw, 1352px" /><figcaption id="caption-attachment-323" class="wp-caption-text">error Management CA saat pembuatan VA</figcaption></figure>
<p>dan terakhir, kalau terjadi masalah dengan file <strong>va-publisher.properties</strong> milik kita, mungkin kita akan melihat pesan berikut:</p>
<pre><strong>06:31:45,632 WARN  [org.ejbca.core.protocol.certificatestore.CertificateCache] (MSC service thread 1-2) org.bouncycastle.ocsp.OCSPException: problem creating ID: java.security.NoSuchProviderException: no such provider: BC</strong></pre>
<p>&#8220;BC&#8221; adalah <strong>Bouncycastle</strong> (OCSP Java Module)</p>
<p>&nbsp;</p>
<p>Itu tadi cara menambahkan Validation Authority ke dalam EJBCA. Untuk pengujian VA tersebut, nantikan postingan selanjutnya ya.</p>
<p>Adios!!!</p>
<h3><a href="http://ejbcacentos.blogspot.co.id/2014/04/how-to-install-ejbca-611-on-centos-65.html"><strong>Source: EJBCACENTOS</strong></a></h3><p>The post <a href="https://blog.goreinnamah.com/blog/2017/02/01/menambahkan-validation-authority-pada-ejbca/">Menambahkan Validation Authority pada EJBCA 6.2.0</a> first appeared on <a href="https://blog.goreinnamah.com">GoBlog</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://blog.goreinnamah.com/blog/2017/02/01/menambahkan-validation-authority-pada-ejbca/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Object Caching 0/161 objects using Memcached
Page Caching using Disk: Enhanced 
Database Caching using Memcached (Request-wide modification query)

Served from: blog.goreinnamah.com @ 2026-10-07 07:34:05 by W3 Total Cache
-->